You need AWS CLI Tools and a IAM Role “AWSCertificateManagerFullAccess” added to this Maschine.
You must split your ssl cert in 3 pieces
aws iam upload-server-certificate --server-certificate-name MySSLCertonAWSÂ --certificate-body file:
//mysslcert.crt --private-key file://myprivatekey.key --certificate-chain file://chain.crt --path /cloudfront/mydomain/